Commit Graph

1993 Commits

Author SHA1 Message Date
Mike Reeves 8304d91b0b Merge branch 'dev' into feature/suri5 2020-05-28 09:41:28 -04:00
Wes Lambert d2b93d531e Basic syslog config 2020-05-28 12:36:29 +00:00
Wes Lambert 5afc05feb2 Update FB init for syslog 2020-05-28 12:35:22 +00:00
Wes Lambert b9bdca509e update Filebeat config for syslog 2020-05-28 12:33:41 +00:00
Doug Burks f3efafc9ca combine two notice queries into one query with multiple groupby 2020-05-28 08:01:33 -04:00
Doug Burks 60cc3e9675 remove address from DHCP leases query 2020-05-28 07:50:52 -04:00
m0duspwnens 59cc927878 Merge remote-tracking branch 'remotes/origin/dev' into issue/749 2020-05-27 15:56:38 -04:00
weslambert 6a935b5452 Hive to TheHive 2020-05-27 15:43:41 -04:00
Josh Brower 11c641fd1b Initial support - integrated Fleet setup 2020-05-27 15:34:14 -04:00
m0duspwnens 12a6da928f create /opt/so/saltstack/local/salt/suricata - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 2020-05-27 15:00:11 -04:00
m0duspwnens 40f04ef6d0 merge with dev and fix conflicts 2020-05-27 13:54:08 -04:00
Wes Lambert b80eb5f73b Add Hive/ES/Cortex scripts 2020-05-27 17:43:17 +00:00
Wes Lambert b26f6826dd Rename Hive to TheHive in several places 2020-05-27 17:17:55 +00:00
Wes Lambert d56bc4c167 fix path 2020-05-27 17:01:05 +00:00
Wes Lambert 3684cdf1c6 Update FB and LS 2020-05-27 17:00:09 +00:00
Wes Lambert e78a3f3278 update Suricata config 2020-05-27 16:59:26 +00:00
Wes Lambert b7a0f79038 Update Suricata init 2020-05-27 16:58:31 +00:00
m0duspwnens 693000afa8 remove addtotab templates and move surirulelink - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 2020-05-27 12:30:12 -04:00
m0duspwnens 446e0f6f4c Merge remote-tracking branch 'remotes/origin/dev' into issue/749 2020-05-27 10:09:36 -04:00
m0duspwnens 7eb02d2af3 move suri rule symlink 2020-05-27 10:09:23 -04:00
weslambert f3809cb93d Wrap with quotes 2020-05-27 08:31:14 -04:00
Mike Reeves 68dd333fbe Remove stats from eve.json 2020-05-26 17:49:11 -04:00
Mike Reeves 1259338e6c Remvoe old Suricata.yml 2020-05-26 17:44:19 -04:00
Mike Reeves 8e95115a7c Update Suricata.yml 2020-05-26 17:43:32 -04:00
m0duspwnens 1eb6142f11 remove dir creation - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 2020-05-26 17:00:29 -04:00
Mike Reeves 8c6928d95a Merge remote-tracking branch 'remotes/origin/dev' into feature/suri5 2020-05-26 15:50:09 -04:00
Mike Reeves 4049df8cb4 Merge pull request #774 from Security-Onion-Solutions/feature/packages
Feature/packages
2020-05-26 15:40:30 -04:00
Mike Reeves b748a86694 Suricata 5 initial commit 2020-05-26 15:12:00 -04:00
m0duspwnens e27facc843 ensure /opt/so/saltstack/local/salt/suricata/rules is created 2020-05-26 14:47:16 -04:00
m0duspwnens 413f08f1b9 change mkdirs to makedirs in ssl state 2020-05-26 14:43:15 -04:00
Mike Reeves 21cd66d109 add ntpdate/ntp 2020-05-26 14:05:47 -04:00
Mike Reeves 41935996d4 add ntpdate/ntp 2020-05-26 13:48:36 -04:00
Josh Brower 894bfd47f4 Merge pull request #771 from Security-Onion-Solutions/feature/communityid-hive-pivot
Elasticsearch Ingest fixes
2020-05-26 13:08:40 -04:00
Josh Brower 8723f8785e osquery pipeline fix and fail state if errors 2020-05-26 13:05:56 -04:00
Doug Burks 7a657d1229 add Community ID to default fields in bottom data table in Hunt 2020-05-26 12:58:01 -04:00
Josh Brower 2cb7464086 Add TheHive communityid link 2020-05-26 12:01:58 -04:00
m0duspwnens fafb469b5c change from default to local - https://github.com/Security-Onion-Solutions/securityonion-saltstack/issues/749 2020-05-26 11:59:00 -04:00
Mike Reeves 87407c9ace rework common init.sls 2020-05-26 11:21:59 -04:00
Wes Lambert 0e51ab41cf Update ES watermark settings 2020-05-26 14:18:58 +00:00
Wes Lambert 97306d3acd rename indices 2020-05-26 14:05:33 +00:00
Wes Lambert 3eb62287ac update Curator config for index transition 2020-05-26 14:00:16 +00:00
Wes Lambert 330de46249 update SOCtopus config for hostname/ip 2020-05-26 13:19:15 +00:00
Wes Lambert e09027e795 update Strelka cron 2020-05-26 13:00:03 +00:00
Mike Reeves 31b3563fb3 Fix package versions 2020-05-24 10:56:30 -04:00
Mike Reeves 1c207afb31 Define packages in the common state 2020-05-23 12:00:24 -04:00
Josh Brower 35f3498ffa Merge pull request #760 from Security-Onion-Solutions/feature/ingest-communityid
Ingest pipeline commid fix for conn logs
2020-05-22 17:11:38 -04:00
Josh Brower 56f5fbdf6b Ingest pipeline commid fix for conn logs 2020-05-22 17:11:08 -04:00
m0duspwnens b24654002b rename salt custom directory to local 2020-05-21 14:53:25 -04:00
Josh Brower 767eda6d60 Merge pull request #754 from Security-Onion-Solutions/feature/ingest-communityid
Feature/ingest communityid
2020-05-21 14:36:08 -04:00
Josh Brower bff86ea802 zeek.common ingest parser fix 2020-05-21 14:35:25 -04:00